Denial of Service Vulnerability in GitList by klaussilveira
CVE-2026-82669
Key Information:
- Vendor
Klaussilveira
- Status
- Vendor
- CVE Published:
- 31 August 2026
Badges
What is CVE-2026-82669?
A vulnerability has been identified in GitList 2.0.0, specifically within the XML Parsing component. The issue lies in the SimpleXMLElement function within the src/SCM/System/Git/CommandLine.php file. An attacker can manipulate this function, leading to a denial of service scenario. This vulnerability can be exploited remotely, and the corresponding exploit is now publicly available. Users are strongly encouraged to upgrade to version 3.0.0-beta, which includes a patch addressing this significant concern. For detailed technical insights and the specific patch, refer to the related GitHub links.
Affected Version(s)
GitList 2.0.0
GitList 3.0.0-beta
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
